Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Package releases #14

Closed
david-gettins opened this issue Dec 6, 2021 · 4 comments
Closed

Package releases #14

david-gettins opened this issue Dec 6, 2021 · 4 comments

Comments

@david-gettins
Copy link

I see your instructions for installation requires me to point to a commit hash from this repository. I find this a little worrying, as a consumer of this package I would like the security of stable releases. Unfortunately pointing to a commit hash provides me with no confidence as I could be pointing to a broken commit.

Please can you set up a release to npm or similar so I can feel safe that the released version is stable in your eyes?

@david-gettins
Copy link
Author

Further to my concerns, the SSH URL does not work during CI. I am not happy adding any SSH related steps to my CI as it could present a security vulnerability on our company's self-hosted build agents.

@david-gettins
Copy link
Author

For now I have forked this repo into my company's org and set up a package push to our private npm registry on GitHub. For anyone else wanting to do this it is quite simple but does not resolve the issue of knowing whether the latest commit is stable, only the library maintainers and contributors can say that.

@elliottkember
Copy link
Collaborator

@david-gettins Hi David! Thank you for your questions. We're working on publishing this package and pointing to it directly from the original NPM alias right now.

Those instructions were for our internal use and were written before we had agreed to take on ownership of the package - sorry for the confusion.

@david-gettins
Copy link
Author

Brilliant thank you for your response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants